MAGNM FIT Privacy Policy
Last updated: September 29, 2026
Operator: Magnum Telehealth LLC
Privacy contact: help@magnumtelehealth.com
This policy explains how the MAGNM FIT mobile app handles information when you use training, nutrition, progress, and AI assistant features. The app offers general fitness and nutrition tools; it is not a medical record system or a substitute for professional care.
Medical records and care. MAGNM FIT does not connect to or import information from Magnum Health patient charts. Information you enter in the app is not automatically added to a patient chart or sent to a clinician for care. Do not use MAGNM FIT to report a medical concern or seek urgent care. The app does handle personal health-related information that you choose to enter, including weight, food allergies, nutrition, and check-ins. This policy describes when that information stays on your device and when a feature sends information to a service provider. We do not assume that all information handled by the app falls outside the scope of protected health information (PHI); that determination depends on how the app and information are used.
Information you provide and where it goes
Account. To sign in, you provide an email address and a one-time code. Our authentication provider, Supabase, processes the email, account identifier, sign-in events, and session information. The app stores your sign-in session in the device’s secure storage.
Fitness and nutrition records. Information you enter into your profile and logs can include your name, goals, training preferences, age, sex used for nutrition calculations, height, weight, body-fat estimate, food allergies, meal preferences, workouts and sets, food and water intake, measurements, check-ins, notes, and saved plans. These records are kept in an account-separated database on your device. Saving a record does not, by itself, upload your fitness log to a MAGNM FIT server. Your device’s backup settings may separately back up app data.
Profile photo. If you choose a photo, the system photo picker gives the app access to the image you select. The app copies that image into its local storage for your account. The current profile-photo feature does not upload the image to our server. You can change or remove it in Profile & settings.
Barcode lookup. If you use the optional barcode scanner, the app uses the camera to read a product code. It sends the code and your authentication token to our app server, which checks your sign-in and requests matching food information from USDA FoodData Central. The barcode digits, rather than a camera image, are used for this lookup. You review the result before anything is saved to your food log. You can also type the barcode instead of granting camera access.
Ares and Athena. Before your first assistant question, you choose whether to allow assistant data sharing. You can change that choice in the assistant’s data-sharing control. If you allow sharing and send a question, the app may send your question, a limited excerpt of the current conversation, and relevant summaries of records saved on your device to our app server. Depending on your question, those summaries may include training, food, hydration, weight, or other progress information. Our server sends the request to OpenAI to generate a response. Assistant messages and saved responses are kept on your device for your signed-in account. The assistant does not continually upload your records in the background; information is sent when you ask it a question. Do not include information in a question that you do not want processed by these services.
App content and links. The Learn section loads public articles and images from Magnum Health. If you open a linked website or consultation page, that site’s own privacy practices apply to your visit and any information you submit there.
Grocery-list sharing. If you choose Share list in Fuel, the app opens your device’s share sheet with a copy of your grocery-list text. The app does not send the list to our server through this feature. The destination app or recipient you choose may receive and handle the list under its own privacy practices.
Our app server and service providers may also process technical information needed to operate these features, such as network address, request time, authentication status, errors, and limited usage counts. We use this information to provide the service, prevent misuse, troubleshoot problems, and manage service limits.
Service providers
The current app uses Supabase for email sign-in, Render to host authenticated barcode and assistant requests, USDA FoodData Central for product lookups, OpenAI for requested AI responses, and Magnum Health for Learn content. The email-code delivery service configured with Supabase may also process your email address. We send information to these providers for the features described above. They may process technical request information to deliver and secure their services. Provider-held logs and backups may remain after an in-app deletion under the provider’s own retention practices; those copies are not removed by the in-app control.
Permissions and your choices
Camera access is requested only if you choose barcode scanning. Photo selection is optional. Notifications are optional for workout rest-timer alerts. You can change these permissions in your device settings; the affected feature may then be unavailable. You can review and change many profile, nutrition, allergy, and log entries within the app. Food allergy filters are aids only: always check product labels and cross-contact information yourself.
Signing out removes this device’s sign-in session, but it does not erase your locally saved fitness or assistant history. The “Start setup over” option only clears specified training setup and workout records; it does not delete the full account or all Fuel and progress records. You can turn off assistant data sharing in the assistant’s data-sharing control; this stops new assistant requests until you allow sharing again, but it does not remove requests already processed.
Retention and deletion
Local records remain on your device until you remove them through available app controls, delete your account, or remove the app. Device backups made before a record is deleted or excluded from backup may retain copies according to your device settings. Account information remains with our authentication provider while your account is active.
Account-linked assistant usage counts on our server are removed when server-side account deletion completes. Render takes daily snapshots of its persistent disk and says they remain available for at least seven days, so an earlier snapshot may contain data removed from the live disk. OpenAI says its default API abuse-monitoring logs can include prompts and responses and are generally retained for up to 30 days, with longer retention when legally required or reasonably needed to protect its services or others. Our assistant requests ask OpenAI not to store the generated response for later retrieval, but that does not prevent abuse-monitoring logs. Supabase, USDA, and any email-delivery provider may retain technical logs or backups under their own policies.
You can initiate account deletion in Profile & settings → Delete account. After our server confirms the request, it deletes your Supabase sign-in account and account-linked assistant usage metadata held in our server’s usage ledgers, then the app removes this account’s saved fitness records, assistant history, and profile photo from the iPhone where you made the request. If the request cannot be confirmed, the app asks you to retry; it does not intentionally remove local records before server confirmation. Other signed-in accounts on that device and older records that were never assigned to an account are separate and are not removed by this control. Our server may keep a one-way fingerprint of the deletion request token in its live retry database to recognize a confirmed deletion without storing the token itself. That live record is set to expire after 30 days and is removed by periodic cleanup; backup copies may last longer under their retention policies. While an interrupted deletion is unresolved, the server may retain the request fingerprint, the verified account identifier, and a hashed account identifier so it can safely finish the request. This automated control does not erase local information from a different device, device backups, provider logs or backups, or AI requests already processed by OpenAI. For help with an interrupted deletion or information outside this automated control, use the contact address below.
To ask about your information, request access or correction, or ask us to review information that the in-app deletion control does not cover, contact help@magnumtelehealth.com. We will verify the request and respond under applicable law.
Changes and contact
We may update this policy as app features or data practices change. The current version and its last-updated date will be shown on the policy page linked from the app and its App Store listing. For privacy questions, contact help@magnumtelehealth.com.